Description
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.
Remediation
References
Related Vulnerabilities
WordPress Plugin YouTube Video Inserter Cross-Site Scripting (1.2.1.0)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-14893)
Python Improper Input Validation Vulnerability (CVE-2018-20852)
WordPress Plugin GD Rating System Unspecified Vulnerability (2.6)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3220)